cfn_nag
vscode-cloudformation-snippets
Our great sponsors
cfn_nag | vscode-cloudformation-snippets | |
---|---|---|
14 | 3 | |
1,219 | 27 | |
0.5% | - | |
0.0 | 8.4 | |
8 months ago | 11 days ago | |
Ruby | Python | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
cfn_nag
-
Setting up my own landing zone on AWS
.pre-commit-config.yaml – contains the cfn-lint and cfn_nag pre-commit hooks.
-
Guide to Serverless & Lambda Testing — Part 2 — Testing Pyramid
For generic CloudFormation templates, check CFN-NAG.
-
AWS Serverless Production Readiness Checklist
If you use CDK, you should implement CDK nag; otherwise, use cfn-nag.
-
Make your life easier using Makefiles
cfn_nag
-
Creating a Multi-Account CI/CD Pipeline with AWS CodePipeline
CodeBuild will run a linting check against the CloudFormation Template using cfn-lint and will then run cfn-nag to check for patterns that indicate insecure resources within the CloudFormation template.
-
App with self-contained infrastructure on AWS
Security checks for the Cloudformation stack using cfn-nag
-
Mastering AWS CDK Aspects
cdk-nag contains several Aspects to check your applications for best practices. It is especially useful if you need to be HIPAA-compliant or have other compliance requirements. It is inspired by cfn_nag which is a a tool checking for patterns in your CloudFormation templates.
-
how did you get good at iac-cloudformation
cfn-lint and cfn_nag or other tools of that nature to check as you write so you don't need to continually try to deploy only to find that you've done something dumb.
-
Source Control your AWS CloudFormation templates with GitHub
There is another tool called cfn_nag that can check your code for potentially any insecure infrastructure. When you read the documentation around this tool, the author says it can check for things such as:
-
Install cfn_nag on Windows
I recently wanted to use the cfn-nag tool on some templates I was writing but couldn't find any instructions to install on Windows, but I have found a way to do it.
vscode-cloudformation-snippets
-
Neovim, LSP and AWS Cloudformation Autocomplete
This appears to be a snippets collection. The actual snippets can be found here.
-
Curated List: Awesome Hackathon Projects
Autocomplete your CloudFormation Resources in VS Code - Autocomplete your CloudFormation Resources in VS Code
-
Cloudformation with Nvim lsp
Snippets have a specific format so if you want that you can easily just copy over any snippets to for example vsnip, for example these https://github.com/dannysteenman/vscode-cloudformation-snippets/tree/main/snippets
What are some alternatives?
checkov - Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
ansible-for-devops - Ansible for DevOps examples.
cfn-python-lint - CloudFormation Linter
taskcat - Test all the CloudFormation things! (with TaskCat)
SonarQube - Continuous Inspection
nvim-lua - Nvim Lua configuration files
aws-secure-environment-accelerator - The AWS Secure Environment Accelerator is a tool designed to help deploy and operate secure multi-account, multi-region AWS environments on an ongoing basis. The power of the solution is the configuration file which enables the completely automated deployment of customizable architectures within AWS without changing a single line of code.
vim-vsnip - Snippet plugin for vim/nvim that supports LSP/VSCode's snippet format.
tfsec - Security scanner for your Terraform code
cfn-lsp-extra - An Experimental Cloudformation language server
cloud-custodian - Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
django-s3file - A lightweight file upload input for Django and Amazon S3